1. Who we are & the scope of this policy
This Privacy Policy explains how Ievgeniia Onokhova, an individual sole proprietor established in California, United States (“kott”, “we”, “us”) collects, uses, shares and protects personal information when you use kott — the browser-based real-time dither, glitch and VJ studio at kott.io — and related services (the “Service”). For the purposes of the EU General Data Protection Regulation (GDPR), the UK GDPR and similar laws, the data controller is Ievgeniia Onokhova, California, United States.
This policy applies to personal information we process as a controller. It does not cover third-party sites or services we link to, or the separate processing carried out by our payment providers as sellers of record (see Section 7). Capitalized terms not defined here have the meaning given in our Terms of Service.
2. The short version
We collect the minimum needed to run your account and the studio. Your camera and microphone are processed entirely on your device — those frames never leave your browser and we never store them or build a biometric template. We do not sell your personal information or share it for cross-context behavioral advertising. Payment card numbers are handled by our payment providers, not by us. You can export or delete your data from your Account.
3. Categories of personal information we collect
We collect the following, mapped honestly to what the Service actually stores:
Account & authentication data. Your email address (used for passwordless magic-link sign-in and held in our authentication system), and account timestamps. We do not store account passwords because authentication is passwordless.
Profile data. Optional fields you choose to add: username, display name, avatar image, short bio, and website URL. If you make a public profile or publish presets, your username, display name, avatar, bio and website may be shown publicly.
Settings & preferences. Your studio and account preferences — theme, reduced-motion preference, default export format and resolution, locale/language, and a small bounded set of editor preferences — and your notification preferences (which product, gallery-activity, comment, tips and marketing emails you want; marketing email is off unless you opt in).
Your content — projects, presets and exports. If you save to the cloud, we store your project files (which may embed the images you place on the canvas), project thumbnails, project version history, and your presets (effect settings/parameters, titles and tags). Projects are private by default; presets and projects only become public if you choose to publish them. Content you keep local/in-browser is not sent to us.
Community & sharing data. If you use community features: which presets you like, any reports you submit about content, and share links you create (including a view counter for each link). If you create or join a team, we store the team name, your role, and invite email addresses used to invite members.
Billing & entitlement data. A mapping between your Account and a customer identifier at our payment provider, your subscription/license status, plan, billing period, seat count and license keys. We never receive or store your full payment-card number; card data is handled by the payment provider (Section 7).
Usage & operational data. Usage counters and export logs (for example, number of exports in a period, storage used, export resolution/format and whether an export was watermarked), and internal audit-log entries for sensitive actions (such as account deletion, plan changes and publishing) used for security and integrity. If you join a waitlist, your email and any referral code.
Technical data from your device. Basic technical information such as IP address, browser/device type and request logs handled by our hosting and infrastructure providers to deliver and secure the Service. If and when privacy-respecting product analytics are enabled (see Section 8 and the Cookie Policy), we may collect limited usage events — only with consent where required.
4. Camera & microphone — 100% on-device (read this section)
Your camera and microphone are processed entirely on your device. When you enable webcam, screen or microphone input, the frames and audio are read and processed transiently in your browser’s memory, in real time, to produce the live visual effect — and are then released. The on-device computer-vision models (for segmentation and detection) and the audio analysis run locally in your browser; the model files are served to your browser and executed there.
Never transmitted or stored. Camera, screen and microphone data is never transmitted to our servers and is never stored by us. It does not leave your device. (If you deliberately export a still or recording and then choose to save it to your cloud projects or publish it, that exported file — not the live camera stream — is handled like any other content you choose to save; see Section 3.)
No biometric identifier or template. kott does not create, capture, derive, receive, collect, purchase or retain any faceprint, face-geometry scan, voiceprint or other biometric identifier or biometric information as those terms are used under laws such as the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), Washington’s biometric and My Health My Data Act (MHMD) provisions, and comparable laws. The on-device segmentation and detection produce only transient rendering data used to draw the current frame; they do not generate an identity record, are not used to identify or authenticate anyone, and are discarded immediately.
Consent. Your browser requires your explicit permission before any website can access your camera or microphone, and it will prompt you the first time. kott also asks for your affirmative in-product consent before it first accesses your camera or microphone: the studio shows a consent notice and does not start the camera unless you agree, and we record that you agreed. You can decline, and you can revoke access at any time from the studio controls or your browser/operating-system settings.
Retention & destruction. Because processing is transient and in-memory on your device, there is nothing for us to retain: no camera, screen or microphone frames are persisted by us, and each frame is released as soon as it is processed. Our retention period for camera/microphone biometric-adjacent data is therefore none: we hold no such data, so there is nothing to destroy on a schedule.
5. Why we process your information (purposes) & legal bases
Where the GDPR or UK GDPR applies, we rely on the following legal bases (Article 6(1)) for each purpose:
To provide the Service and your account — create and authenticate your Account, store your settings, and sync your projects and presets. Legal basis: performance of a contract (Art. 6(1)(b)).
To process payments and manage plans — via our payment processor, and to maintain your license or subscription status. Legal basis: performance of a contract (Art. 6(1)(b)) and, for tax and accounting records, legal obligation (Art. 6(1)(c)).
To operate community and sharing features — display published presets and public profiles, resolve share links, and count views/likes. Legal basis: performance of a contract and our legitimate interests in operating these features (Art. 6(1)(b) and (f)).
To secure the Service and prevent abuse — audit logs, fraud/abuse prevention, enforcing our Terms and Acceptable Use Policy, and moderation. Legal basis: legitimate interests (Art. 6(1)(f)) and legal obligation where applicable.
To communicate with you — service and transactional emails (always), and product/marketing emails only where you have opted in or as otherwise permitted. Legal basis: consent (Art. 6(1)(a)) for marketing, legitimate interests / contract for transactional messages.
To understand and improve the product — limited, privacy-respecting analytics, only when enabled and, where required, only with your consent (Art. 6(1)(a)); otherwise legitimate interests (Art. 6(1)(f)).
Enabling your camera or microphone in the studio does not create any transmission to us, so no separate legal basis is engaged for us in respect of those frames; your interaction with the on-device feature is under your own control and consent.
6. How long we keep your information (retention)
| Data | Retention |
|---|---|
| Account, profile & settings | While your Account is active; deleted after account deletion (subject to backups below) |
| Projects, presets & exports (cloud) | Until you delete them or delete your Account |
| Billing / license records | Kept after the last transaction for as long as applicable tax and accounting law requires us to keep them |
| Usage counters & audit / security logs | Usage counters: while your Account is active. Administrative audit records (for example issuing or revoking a license) are append-only and kept indefinitely as a security record; where they reference a deleted account, the reference to you is removed |
| Camera / microphone frames | None — transient, in-memory on your device only (Section 4) |
| Backups | Deletion takes effect in the live system straight away; residual copies age out on our hosting provider’s rolling backup cycle and are overwritten rather than restored |
When you delete your Account, we delete or de-identify your personal information within a reasonable period, except where we must retain it to comply with law, resolve disputes, or enforce our agreements, and except for residual backup copies that are overwritten on the cycle above.
7. Who we share information with (subprocessors)
We do not sell your personal information. We share it only with service providers (subprocessors) that process it on our behalf under contract, and where required by law or to protect rights and safety. Current and planned subprocessors:
| Provider | Purpose | Status |
|---|---|---|
| Supabase | Authentication, database & file storage | Active |
| Vercel | Application hosting / delivery | Active (deployment) |
| Stripe | Payment processing for every kott purchase — the kott licence, and the earlier Plans and licenses. Processor only: not a merchant of record, not the seller. We are the seller of record and handle our own tax | Active |
| Paddle | Merchant of record for unhtml, a separate product of ours (a Figma plugin) whose license keys are issued from this site. No role in any kott purchase | Active (unhtml only) |
| Resend | Transactional / product email | When enabled |
| PostHog | Privacy-respecting product analytics | When enabled (consent-gated) |
| Sentry | Error / crash reporting | When enabled |
Payment data. We are the seller of record for every kott purchase — the browser studio and Kott for macOS are covered by one licence, and the same was true of the earlier Plans and licenses — and Stripe processes the card transaction on our behalf as our processor. Stripe is not a merchant of record and does not sell the product to you. We receive only limited billing metadata, never your full card number. Paddle appears above only as the merchant of record for unhtml, a separate product of ours, where it processes buyer payment details as an independent controller under its own privacy notice; it handles no kott purchase. We may also disclose information to comply with law, respond to lawful requests, or protect the rights, property or safety of kott, our users or the public. If we are involved in a merger, acquisition or asset sale, personal information may be transferred subject to this policy. The table above is our current subprocessor list; we will provide details of the data-processing agreements behind it on request at support@kott.io.
8. Cookies & similar technologies
We use a small number of cookies and local-storage items — for authentication (essential), for remembering your studio/theme preferences on your device (functional), and to record your consent choices. Any analytics storage is set only where enabled and, where required, only with your consent. See our Cookie Policy for the full list and how to change your choices, and Section 10 for how we honor Global Privacy Control.
9. International data transfers
We and our subprocessors may process personal information in countries other than yours, including the United States and the European Union. Where we transfer personal information from the EEA, the UK or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards — principally the European Commission’s Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, and, where a provider is certified, the EU-U.S. / UK / Swiss Data Privacy Framework (DPF) — together with supplementary measures as needed. We are established in California, United States, so personal information you provide is processed in the United States. You may request a copy of the relevant safeguards at support@kott.io.
10. Your privacy rights
EEA / UK (GDPR & UK GDPR). You have the right to access your personal data; to rectify inaccurate data; to erase data (“right to be forgotten”); to restrict or object to processing (including processing based on legitimate interests, and direct marketing at any time); to data portability; and, where processing is based on consent, to withdraw consent at any time without affecting prior processing. You also have the right to lodge a complaint with the data- protection supervisory authority in your country of residence or workplace. Because we have no establishment in the EU or the UK, there is no single lead supervisory authority for kott — your own national authority is the right one to approach. We provide in-Account data export and account deletion to help you exercise these rights, and we sign data-processing agreements with our subprocessors.
California (CCPA / CPRA) & other U.S. state laws. If you are a California resident (or a resident of a state with a comparable law, such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and others), you have the right to know/access, delete, and correct your personal information, to data portability, and to opt out of the “sale” or “sharing” of personal information and of certain profiling. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We honor the Global Privacy Control (GPC) browser signal as a valid opt-out of sale/sharing. We do not use or disclose sensitive personal information for purposes that require an opt-out right. We will not discriminate against you for exercising your rights. You may designate an authorized agent to make a request on your behalf.
Canada (PIPEDA). If you are in Canada, you may request access to and correction of your personal information and may withdraw consent, subject to legal or contractual limits. You may also complain to the Office of the Privacy Commissioner of Canada.
Brazil (LGPD). If you are in Brazil, you have rights to confirmation of processing, access, correction, anonymization/blocking/deletion, portability, information about sharing, and to withdraw consent, and you may contact the ANPD.
Australia (Privacy Act / APPs). If you are in Australia, you may request access to and correction of your personal information and may complain to us and then to the Office of the Australian Information Commissioner (OAIC).
How to exercise your rights. Use the export and delete tools in your Account settings, or contact us at support@kott.io. We will verify your identity (usually via your Account email) and respond within the timeframe required by applicable law. These rights are free to exercise, subject to limited exceptions for manifestly unfounded or excessive requests.
11. Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13 (or under the higher minimum age that applies to you under Section 3 of our Terms). We use a neutral age gate at sign-up and do not knowingly onboard under-age users. Because camera and microphone processing is on-device and never transmitted to us, our exposure is minimized. If you believe a child has provided us personal information, contact support@kott.io and we will delete it consistent with the U.S. Children’s Online Privacy Protection Act (COPPA) and other applicable law.
12. Data security
We use technical and organizational measures appropriate to the risk — including encryption in transit, access controls, row-level security on our database, scoped storage buckets (private by default for your projects), and least-privilege service credentials — to protect personal information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security; you are responsible for keeping access to your Account email secure and for backing up important work.
13. Data breach notification
If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required by law (for example under the GDPR/UK GDPR or applicable U.S. state breach laws), affected users, within the timeframes the law requires, and describe the nature of the breach and the steps you can take.
14. Changes to this policy
We may update this policy from time to time. We will change the “Last updated” date above and, for material changes, provide additional notice (for example by email or an in-Service notice). Your continued use after a change takes effect constitutes acceptance to the extent permitted by law; where the law requires consent for a change, we will seek it.
15. kott for macOS (desktop app)
Kott for macOS — the downloadable desktop version of the studio, covered by the same one-time kott licence as the browser studio — is designed to run fully offline after a one-time license activation. It has no account, no telemetry, no analytics, and no crash-report uploading. Any crash diagnostics stay on your Mac and are never uploaded to us. Your camera, screen and microphone are processed on your device exactly as described in Section 4.
The only network requests the app makes. The desktop app makes exactly two kinds of network request, and no others:
(a) One-time license activation. On first launch, the app contacts our activation endpoint once to validate your license key. This request sends only your license key, a random install identifier for that Mac, and the app version — nothing else. It does not send your name, email, files or any usage data. After a successful activation the app works offline and does not phone home again.
(b) Update check. The app checks our public release feed on GitHub releases for a newer version and downloads it if you update. If you are offline, this check fails silently and the app keeps working.
No personal data beyond your purchase email. For the desktop app we do not process any personal data about you beyond the email address used for your purchase, which is held by Stripe as our payment processor (Section 7) and in our license database so we can issue, support, and — where a purchase is refunded or charged back — revoke your license key. The random install identifier described above is not linked to your identity beyond your key. For the full desktop license terms, see the kott for macOS License Agreement.
16. Contact us
Data controller: Ievgeniia Onokhova — individual sole proprietor (no company registration)
California, United States
Privacy contact: support@kott.io
Data Protection Officer: none appointed — kott is run by one person, and privacy requests go to the address above
EU / UK representative (Art. 27 GDPR): none appointed
Related policies: Terms · Cookies · Refunds · Acceptable Use · DMCA · Desktop App License